CyberMax
Home › Glossary › Vulnerability management

What is CVSS?

Vulnerability management glossary · 2 primary sources

Common Vulnerability Scoring System: FIRST's standard 0.0–10.0 score for how severe a vulnerability is, based on how it can be exploited and what it affects.

The base score is computed from a vector of metrics. In CVSS v3.1 they are attack vector, attack complexity, privileges required, user interaction, scope, and the impact on confidentiality, integrity and availability. The qualitative ratings are None (0.0), Low (0.1–3.9), Medium (4.0–6.9), High (7.0–8.9) and Critical (9.0–10.0).

CVSS v4.0 (published in 2023) splits the score into base, threat, environmental and supplemental groups and names results like CVSS-B or CVSS-BT to show which groups were used.

CVSS measures severity, not likelihood: a 9.8 that nobody exploits can matter less than a 7.5 in the KEV catalog. That is why it is usually combined with EPSS and KEV.

Example: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H = network attack, low complexity, no privileges or user action needed, high impact on all three: base score 9.8 (Critical).

Sources

Related terms

On this site

All vulnerability management terms · Full glossary